Skip to content

Commit

Permalink
Update index.md (#480)
Browse files Browse the repository at this point in the history
Restructure and revise the index OWASP.org Project index page. to refeect the current project scope and addition of links for the new 2025 Top 10 for LLMS

Signed-off-by: sclinton <[email protected]>
  • Loading branch information
SClinton authored Nov 19, 2024
1 parent 17bfc16 commit 6ee34b9
Showing 1 changed file with 15 additions and 21 deletions.
36 changes: 15 additions & 21 deletions index.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,37 +7,31 @@ tags: example-tag
pitch: Aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)
---

The OWASP Top 10 for Large Language Model Applications project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs). The project provides a list of the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications. Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications. You can read our [group charter](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Charter) for more information
The OWASP Top 10 for Large Language Model Applications Project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs) and Generative AI applications. The project provides a range of resources. Most notably the OWASP Top 10 list for LLM applications listing the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications.

Review the official 2025 release ([Full Version](assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf) to understand work that has been done to date.
Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications.

# 📢 New Document Release: Security & Governance Checklist
## 📢 The 2025 List is Available:
Download OWASP Top 10 for LLMs List for 2025 [Full Version](https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/).

We're excited to announce version 1.0 of our latest document: **Security & Governance Checklist**. This comprehensive guide is essential for a Chief Information Security Officer (CISO) managing the rollout of Gen AI technology in their organization.
## Download Additional Resources from our [Website](https://genai.owasp.org) including:
- [Security & Governance Checklist v1.0](https://genai.owasp.org/resource/llm-applications-cybersecurity-and-governance-checklist-english/) Essential guidance for CISOs managing the rollout of Gen AI technology.
- [Guide for Preparing and Responding to DeepFakes](https://genai.owasp.org/resource/guide-for-preparing-and-responding-to-deepfake-events/)
- [2025 AI Security Solutions Directory and Guide](https://genai.owasp.org/ai-security-solutions-landscape/)

🔗 [Download the PDF here](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1.1.pdf) - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)

# 📢 New Website Launched: Check us out there as well

We have launched a [new website](https://genai.owasp.org) to complement this one.

This initiative is community-driven and encourages participation and contributions from all interested parties.
## Localized versions are also available.
- Security & Governance Checklist v1.0 - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)

## Want to Contribute your Expertise? Join us.
- We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-for-llm channel.
- The working group is collaborating on our [wiki](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki)
- Want to stay updated on periodic progress? [Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) or [Follow our project LinkedIn page](https://www.linkedin.com/company/owasp-top-10-for-large-language-model-applications/)

## Just Want to Learn About LLM Security
New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.

## Become a Project Suppoter or Sponsor Sponsorship
We are a not for profit open source community driven project, interested in supportign teh project with reasources or become a sponsor to help us ensure we can continue to sustain the community efforts, offsetting operational, and outreach costs. Visit the [Sponsor Section](https://genai.owasp.org/sponsorship) on our website.

## Thank you to our Current [Sponsors and Supporters](https://genai.owasp.org/supporters/)

## Project Sponsorship

### Learn how to become an [OWASP LLM Project Sponsor/Donor](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Donors-and-Project-Sponsors).

We are just launching a new project sponsor program. The OWASP Top 10 for LLMs project is a community-driven effort open to anyone who wants to contribute. The project is a non-profit effort and sponsorship helps to ensure the project's sucess by providing the resources to maximize the value communnity contributions bring to the overall project by helping to cover operations and outreach/education costs. In exchange, the project offers a number of benefits to recognize the company contributions.


## Supporters

Sponsor Logos Comming soon.

0 comments on commit 6ee34b9

Please sign in to comment.